2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100587 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation c... |
| CVE-2026-100586 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings.... |
| CVE-2026-100585 | HIGH | 8 | — | Sep 26, 2026 | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude C... |
| CVE-2026-100580 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a m... |
| CVE-2026-100579 | HIGH | 7.6 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity... |
| CVE-2026-100578 | HIGH | 7.6 | — | Sep 26, 2026 | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the ... |
| CVE-2026-100575 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disa... |
| CVE-2026-100570 | HIGH | 7.8 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the... |
| CVE-2026-100568 | HIGH | 8.3 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible... |
| CVE-2026-100567 | HIGH | 8.2 | — | Sep 26, 2026 | OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gate... |
| CVE-2026-100561 | HIGH | 8 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec appro... |
| CVE-2026-100560 | HIGH | 7.5 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact c... |
| CVE-2026-100559 | HIGH | 8 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist p... |
| CVE-2026-100558 | HIGH | 7.5 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauth... |
| CVE-2026-100557 | HIGH | 8.3 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to car... |
| CVE-2026-100555 | HIGH | 7.1 | — | Sep 26, 2026 | OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment del... |
| CVE-2026-100552 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server... |
| CVE-2026-100551 | HIGH | 8.3 | — | Sep 26, 2026 | OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While nat... |
| CVE-2026-100544 | HIGH | 8.8 | — | Sep 26, 2026 | openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls wi... |
| CVE-2026-100543 | HIGH | 7.5 | — | Sep 26, 2026 | OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacte... |
| CVE-2026-100541 | HIGH | 7.5 | — | Sep 26, 2026 | OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matr... |
| CVE-2026-100535 | HIGH | 7.5 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions ... |
| CVE-2026-100532 | HIGH | 8.1 | — | Sep 26, 2026 | @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without p... |
| CVE-2026-100530 | HIGH | 7.3 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved c... |
| CVE-2026-100520 | HIGH | 8.8 | — | Sep 26, 2026 | Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now